Live data from Hacker News

Google and Facebook accused of breaking GDPR laws

bbc.com

351–360 of 384 posts

Re: Google and Facebook accused of breaking GDPR laws

#351
post #258

Earlier quoted context omitted.

> EU can't wait to give fat fines to companies like Facebook and Google, due to their tax evasion schemes. How does GDPR relate to "tax evasion" at all? Also, Google and FB set up to pay taxes in Ireland, which is a member of the E.U. That seems legal to me. See https://en.wikipedia.org/wiki/Double_Irish_arrangement

The 4% of worldwide revenue aspect is almost exclusively pointed at the giant US tech companies. Europe has few meaningfully large tech companies, with large global sales, such that taxing worldwide revenue matters (this is why they didn't just make it an EU revenue tax). It's meant to try to plunder some of the global revenue that Google, Facebook, Microsoft, Netflix, Apple, Amazon, Twitter, Snapchat, etc. are gener…

> who the hell taxes revenue, instead of profit, other than the backwards Russian state anyway?

Both Washington and Texas for starters....

Re: Google and Facebook accused of breaking GDPR laws

#352
post #309

Earlier quoted context omitted.

> non-targeted ads suck as they usually end up being like Viagra ads since they pay the most. Ads on TV have been non-targeted since the TV was invented, TV stations have survived thus far and are doing a little better than online publishers. Note that we are talking of tracking individuals. You can still say a lot about the demographics of a TV show and thus do ads targeting based on the actual content being watched…

> Saying that tracking individuals is necessary for getting revenue is disingenuous. I'm definitely not saying that. I'm saying non-targeted ads generate a lot less money than targeted ones which means the content on the internet won't be as good as companies will generate less money to pay for the content. In the extreme cases as we are seeing now, businesses are shutting down or blocking all EU users because the pe…

Shutting down or blocking all EU users is perfectly fine by me. At least I'd know which are the companies I should stay away from.

But no, it won't happen, because the EU is the world's second biggest market. If China can afford to coerce companies into censorship and violating people's rights, the EU can afford to impose some privacy laws as well.

And as I've been saying elsewhere, targeted ads are only needed at this point because people are fed up with ads due to abuse, this being a race to the bottom anyway. Pretty soon targeted ads won't work well either, how well they work right now is questionable and all of that data will have been collected already, ready to be sold and abused.

Re: Google and Facebook accused of breaking GDPR laws

#353
post #234

Earlier quoted context omitted.

That is entirely false. If you buy from the Google store, you'd have to agree before buying (you can't buy without an account). If you don't, then the seller had to notify you before your purchase. Google had little influence there. And your argument doesn't work if you're taking about third party devices, which the parent was. Android itself is open source. OEMs aren't forced to bundle the Google services with it. T…

Google has a checklist of things that each OEM has to do in order to distribute the Google Apps, which are not open source. If the OEMs are in compliance with Google's terms for OEM distributors, I would say that it is an issue with Google's terms. I am curious, I have a Samsung device and I note that I can't uninstall Gmail. Is that Google's choice or Samsung's choice?

honestly, i think the best choice would be to 'accept', and use the google services, or deny -- and just not get any google apps installed.

this would give privacy oriented people the option to simply opt out of anything google and still uphold the pretty good stock experience.

but this is imo still not google's task. OEMs choose to just flash google's services and apps by default right into their OS. that should only be done after the user said 'yes, i want to tell google everything i do'

Re: Google and Facebook accused of breaking GDPR laws

#354

Earlier quoted context omitted.

You have deviated into the absolutist approach I mentioned before. You don't even have to do without regulation, just not more and larger. Among solutions there includes: education, enforcement of existing statutes, reduced scope legislation until enforcement catches up, promotion of alternative approaches, tacit support for technical defenses, etc, etc. There are so many more. Adopting this large sweeping legislatio…

GDPR really isn't that much more than the previous DPA which was in place 20 years without problem. Businesses and startups were still formed. To stick to the general. Who pays for education and promotion of alternatives against industries spending billions? Either it's coming out of tax or a regulation is required to force educational messages and disclaimers. If neither it just seems a way to assert the status quo…

I think anti social media PSAs are as reasonable as any other PSAs. It's ok to encourage people to go outside instead of play video games or encourage people to not talk on the phone while driving. The video game and phone industries are big too. It's ok to give grants to projects that already have other players in the industry. It's ok to suggest people use ad block. There's no need to be so defeatist assuming nothing will work. We can't even really discuss these types of solutions if everything but law is assumed to not work for internet privacy issues when law is the only one that has been shown not to work. Absolutist phrases like "unrestricted commerce" (as though that exists) "regulation [...] only viable way left" are the reason nobody can see alternatives. It's like self-imposed blinders.

Re: Google and Facebook accused of breaking GDPR laws

#355
post #88

Earlier quoted context omitted.

Hmm, seems you are right, I just found this PDF from the ICO: https://ico.org.uk/media/about-the-ico/consultations/2013551... "Avoid making consent a precondition of a service" "consent requests must be separate from other terms and conditions. Consent should not be a precondition of signing up to a service unless necessary for that service" I assume Facebook et al will simply find a way to make everything 'necessary…

For consent this is true, but there are other legal ways for you to collect the data. One is legitimate interest, this one is more abstract but requires a bit more work from you. I think a lot of the future court cases will be around trying what one can use legitimate interest for. https://ico.org.uk/for-organisations/guide-to-the-general-da...

Legitimate interest is meant for when it's in the user's best interest... but I've no doubt that, given sufficient lawyers, Facebook et al could argue almost any data-hoovering is in their users best interest

Re: Google and Facebook accused of breaking GDPR laws

#356

Earlier quoted context omitted.

> Your registrar is almost certainly a lot easier to phish/social engineer/whatever than Google. Please don't spread unsourced FUD. I'm not saying registrars are perfect (although Gandi, which I linked, has an impeccable track record), but everyone uses registrars for their domain name, even the biggest businesses out there. If you have a problem with a particular registrar, I invite you to source it and share it. Bu…

I'm not spreading FUD. I'm spreading Maciej Ceglowski's information: https://techsolidarity.org/resources/congressional_howto.htm... @pinboard has explained on Twitter that registrars can get tricked into letting an attacker into your domain account (of course they can). And from there they can update your zone file to send your mail wherever they want. This isn't about the storage of your email.

Even if such an attack were to take place, that doesn't mean you don't "own" your email. You own it far more than an @gmail.com address...

Re: Google and Facebook accused of breaking GDPR laws

#357
post #265

Earlier quoted context omitted.

Why do you think that previous ToS was outdated and no longer legally valid? Why do you think consent given x years earlyer would not be valid?

Because the new law says the user can’t be assumed to consent, unless the specific parts of the contract are stated more explicitly, are opt-in rather than opt-out, etc. The old ToS become invalid and unenforceable. If they stop collecting data for those users (at least until they opt in to an updated ToS) that would work around the problem.

Anyway, I'm in EU and I received mailon 12th may about updated privacy policy. In my native language that is used only by <2m ppl.

Re: Google and Facebook accused of breaking GDPR laws

#358
post #261

Earlier quoted context omitted.

I don't understand how a facebook post made by me 'belongs' to me. It was addressed to specific audience that facebook made available to me, it wouldn't have existed in the first place if facebook didn't exist. How does it completely belong to me.

If you make a song on a Gibson guitar, should the song belong to Gibson?

I think your analogy holds true for the documents you write on MS word that you bought. Posting on facebook is equivalent to recoding on a song in Gibson's studio, in which case it doesn't completely belong to you.

Re: Google and Facebook accused of breaking GDPR laws

#359

Earlier quoted context omitted.

I am using a chinese noname Android phone without a Google Account. It is somewhat useable even without Internet connection and without SIM card. For example, I can use a camera, radio, music player, a dictionary or offline maps.

China gets your data now.

That's why I thought about either routing all traffic through my server or replacing proprietary ROM with open source software.

Re: Google and Facebook accused of breaking GDPR laws

#360

Earlier quoted context omitted.

The literal text of the GDPR is as follows: >the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

Yes, and before that it says ` If the data subject's consent is given in the context of a written declaration which also concerns other matters,` which means i can use legalese but only if it does not concern other matters in the same document? :)

You'd hope not, but I also thought the phrasing in that sentence was sloppy.
Post reply on HN